CVE-2005-1975

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/06/2005
Last modified:
03/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:annuaire:1two:*:*:*:*:*:*:*:* 1.1 (including)
cpe:2.3:a:annuaire:1two:1.0:*:*:*:*:*:*:*